summaryrefslogtreecommitdiff
AgeCommit message (Collapse)Author
2024-10-09Replace Keycloak with KanidmJoe Mou
Keycloak has always been heavyweight and cumbersome. Kanidm is meant to be an all-in-one Rust identity provider instead. $ sudo kanidmd recover-account idm_admin $ kanidm login --name idm_admin $ kanidm group account-policy credential-type-minimum idm_all_persons any $ kanidm person create joe Joe $ kanidm person credential update joe $ kanidm system oauth2 create oauth2-proxy 'OAuth2 Proxy' https://op.mou.fo $ kanidm system oauth2 update-scope-map oauth2-proxy idm_all_persons openid profile email $ kanidm system oauth2 show-basic-secret oauth2-proxy Passkeys don't work with KeePassXC on Firefox. They might work with Chrome or BitWarden. We disable TOTP for password authentication. Kanidm itself has considered and rejected forward auth support per https://github.com/kanidm/kanidm/issues/2774 With this arrangement session cookies are about 2k. While large these should fit within the default nginx buffers. Dex can be used as a simple identity provider, although it is more designed to facilitate app authentication. It can be configured to have a workable configuration with no persistent state and only staticClients and staticPasswords for resource servers and users. Vouch Proxy is comparable with oauth2-proxy. Both assume the user has an e-mail which we don't use. However oauth2-proxy seems to have better workarounds and is somewhat more actively maintained. Vouch Proxy also lacks a NixOS module. https://discourse.nixos.org/t/configuring-vouch-proxy-or-oauth2-proxy-nginx-nix/19337/2 https://github.com/vouch/vouch-proxy/issues/309
2024-10-09Try out GiteaJoe Mou
DISABLE_REGISTRATION needs to be set after the initial administrator account is manually registered. Considered the Forgejo community fork, but it doesn't seem to have attracted very much of the developer community. Despite concerns about copyright claims, Gitea does not have a CLA; it is MIT licensed. Still considering even lighter weight options that may be easier to programmatically control (just an HTTP server that speaks the smart protocol?). For managing groups of repositories, can use labels or organizations. Neither seem particularly convenient. Gitea defaults to public repositories.
2024-10-09Update Syncthing hostsJoe Mou
2024-10-09Refactor HA helper functionsJoe Mou
Based on https://github.com/nathan-gs/nix-conf/blob/main/lib/ha.nix (which goes further in using the module system; see https://nathan.gs/2023/12/09/adding-helper-functions-to-nixos/ )
2024-10-09Control AC with bedroom temperature sensorJoe Mou
2024-10-09Adjust adaptive_lighting parametersJoe Mou
2024-10-09Remove poor IPv6 support from dynamic DNSJoe Mou
2024-10-09sshguard whitelist to prevent lockoutJoe Mou
2024-10-09HA: adaptive_lighting custom component to follow daylightJoe Mou
2024-10-09Switch from unmaintained libreddit to redlibJoe Mou
2024-10-09Simplify NitterJoe Mou
- Populate OAuth tokens using justajoedoe. - Use binary cache build of Nitter.
2024-10-09First attempt at NitterJoe Mou
2024-10-09Grow light cycleJoe Mou
2024-10-09Upgrade to NixOS 24.05Joe Mou
To resolve database collation version mismatches ("The database was created using collation version 2.38, but the operating system provides version 2.39."): $ sudo -u postgres psql > \c hass > REINDEX DATABASE hass; > ALTER DATABASE hass REFRESH COLLATION VERSION; [ Repeat for all databases (except special database template0) ]
2024-06-11locate/updatedbJoe Mou
2024-06-11Fix dynamic DNS retries and e-mail alert throttlingJoe Mou
2024-05-25Grow light as alarm automationJoe Mou
2024-05-25Update Syncthing shares (remove weeber)Joe Mou
2024-05-06HA: improve panel light and thermostat automationsJoe Mou
Also fixes missing component errors.
2024-04-27E-mail on rebootJoe Mou
mailutils (but not sendmail) addresses from the unqualified hostname
2024-04-27elmo: Hoist subdomains and issue production certificatesJoe Mou
2024-04-26elmo: E-mail on certain systemd failuresJoe Mou
2024-04-26elmo: postfix with client certificatesJoe Mou
2024-04-26elmo: Enable sshguardJoe Mou
2024-04-26ACME with DNS challengeJoe Mou
2024-04-26elmo: blocky ad-blocking DNSJoe Mou
2024-04-26elmo: simplify SIG(0) key managementJoe Mou
2024-04-26elmo: nzbgetJoe Mou
2024-04-26elmo: move syncthing to /srvJoe Mou
2024-04-26elmo: /srv subvolumeJoe Mou
The intention is to separate user-managed data, like backups and file shares. Still need to move syncthing over. An implication is /srv will probably not participate in restic backups but be replicated in some other way.
2024-04-26elmo: Enable fstrimJoe Mou
Initial run trimmed nearly the entire volume. May be quite important since Nix churns through storage.
2024-04-26elmo: Move secrets to /var/secretsJoe Mou
Clarifies that they are not managed by a distribution package.
2024-04-26Use SSH host alias for elmoJoe Mou
2024-04-26libreddit tweaksJoe Mou
2024-04-23Panel light and thermostat HA automationsJoe Mou
2024-04-23Initial HA automations (panel light & bedroom thermostat)Joe Mou
2024-04-15commentsJoe Mou
2024-03-20creep: configure WiFi AP that tunnels over VPNJoe Mou
2024-03-12creep: ensure IPv4 dyndns updatesJoe Mou
2024-03-12creep: static network configuration instead of NetworkManagerJoe Mou
2024-03-12creep: reverse SSH tunnel and dynamic DNSJoe Mou
2024-03-12creep: add swapJoe Mou
Contravenes guidance to avoid edits to hardware-configuration.nix
2024-03-12Streamline elmo configJoe Mou
2024-03-11creep: initial configurationJoe Mou
2024-02-18Enable mDNSJoe Mou
2024-02-18use tmpfs for /tmpJoe Mou
2024-02-18Add mac mini SSH key and SyncthingJoe Mou
2024-02-18Update and fix up tuya-local packagingJoe Mou
2024-02-18Boot after power failure (server mode)Joe Mou
2024-02-15Move /var to larger hard driveJoe Mou